Overview
- Security firm Huntress traced at least 40 incidents to the campaign and confirmed two infections that began on attacker‑created Custom GPT pages hosted on chatgpt.com.
- The delivery path used sponsored Google search results to land victims on a Custom GPT that redirected them to a Google Sites page posing as a Cloudflare CAPTCHA which instructed users to paste and run a PowerShell command.
- That command downloaded an MSI which launched a heavily obfuscated eight‑stage chain that sideloaded a legitimately signed host executable and loaded a loader hidden inside carriers such as WAV files or NuGet packages.
- The final payload is a resilient RAT that supports remote desktop, camera and microphone capture, file search and drop‑and‑run of follow‑on payloads, uses DNS‑over‑HTTPS for command‑and‑control, and creates persistence via a Run key and a scheduled task named 'Canon Configuration Reader'.
- OpenAI removed the first malicious Custom GPT on September 25 and a replacement appeared on September 27 as operators swapped signed hosts and carriers to evade takedowns, so Huntress urges behavior‑based detections and user training to block PowerShell→msiexec MSI installs, signed apps running from unusual AppData folders, and reappearing Run/task persistence.